Please sync xz-utils 5.6.0-0.2 from Debian experimental

Bug #2055422 reported by Adrien Nader
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
xz-utils (Ubuntu)
Invalid
Undecided
Unassigned

Bug Description

NOTE: THE VERSION MENTIONED HERE HAS BEEN BACKDOORED.
I am keeping the text below unchanged due to its possible historical relevance.

======

Xz-utils 5.6.0 was released last Friday. It features a much faster decompression code on all platforms but on x86_64 in particular, it is 60% faster in my testing. It also aligns better current practices of enabling multi-threading by default (always with a default memory limit of 25% of the system physical memory).

Sebastian Andrzej Siewior has uploaded it to experimental and after a few fixes for integration (due to extra output on stderr in particular), has uploaded xz-utils 5.6.0-0.2.

I expect tests to pass now considering they almost all succeeded with the first upload.
I am aware of tweaks to other packages too but I'm not sure they will actually be needed with this new upload and since they relate to pristine-tar and/or dpkg, I think it's probably better to be sure first due to the ongoing migrations.

Thanks.

CVE References

Revision history for this message
Adrien Nader (adrien) wrote :

Graham pointed out that the upload was actually to unstable and therefore autosync'ed already!

I'm going to keep the bug open until it migrates due to the possibility of some testsuite failures.

Revision history for this message
Sergio Oller (zeehio) wrote :

I just read about the backdoor on xz-utils from CVE-2024-3094 (not yet synced to Launchpad CVE, I can't use the Link to CVE feature) and I wanted to know more about Ubuntu's status.

Please avoid syncing any vulnerable version.

Revision history for this message
Adrien Nader (adrien) wrote :

I had forgotten about this bug. Thanks for bringing this up and let me close this.

Changed in xz-utils (Ubuntu):
status: New → Invalid
description: updated
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.